Federal Risk and Authorization Management Program
FedRAMP is a U.S. government program under GSA that standardizes cloud security authorization for federal agencies, operating a marketplace of 529 certified cloud services through its FedRAMP 20x and Rev5 certification paths.
- Company typePublic
- Founded2011
- HeadquartersAlexandria, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Federal Risk and Authorization Management Program does
FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration's (GSA) Technology Transformation Services (TTS) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. The program was established in 2011 and is formalized under the FedRAMP Authorization Act and OMB Memorandum M-24-15, making FedRAMP authorization effectively mandatory for cloud services sold to the federal government. It serves two primary constituencies: federal agency buyers that need compliant cloud solutions, and cloud service providers (CSPs) that must obtain authorization before selling into the federal market.
The core platform consists of the FedRAMP Marketplace, a searchable database listing 529 certified cloud services alongside authorizing agencies and recognized third-party assessment organizations (3PAOs), and the Consolidated Rules for 2026 (CR26), a unified ruleset launched June 25, 2026 that replaces legacy scattered guidance. The program supports two certification paths: FedRAMP 20x, the modernized cloud-native path that reached general availability on June 25, 2026 (29 services certified to date), and Rev5, the legacy path being phased out with no new applications accepted after June 11, 2027. Underlying technical components include machine-readable JSON schemas defining submission artifacts (vulnerability reports, incident reports, security decision records, ongoing certification reports), a centralized Security Inbox for urgent CSP communications (effective January 5, 2026), and structured rules in both JSON and human-readable formats.
As a federal program, FedRAMP does not generate commercial revenue. It is funded through federal appropriations under GSA and provides its services free of charge to federal agencies, while CSPs bear the cost of third-party assessments and documentation preparation. The program's distribution model is a centralized marketplace combined with two authorization pathways: Agency Authorization (requiring a federal sponsor) and the newer Program Certification under FedRAMP 20x. Community engagement is conducted through monthly meetings (20x Community Updates, Agency Liaison Meetings, Agency Support Group Meetings, Rev5 Community Updates), GitHub community discussions, Requests for Comment, and the Federal Secure Cloud Advisory Committee (FSCAC).
Federal Risk and Authorization Management Program firmographics
Firmographics- Name
- Federal Risk and Authorization Management Program
- Legal name
- Federal Risk and Authorization Management Program (FedRAMP)
- Website
- https://fedramp.gov
- Company type
- Public
- Founded year
- 2011
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- FedRAMP is a U.S. government program under GSA that standardizes cloud security authorization for federal agencies, operating a marketplace of 529 certified cloud services through its FedRAMP 20x and Rev5 certification paths.
- Ownership category
- akta.pro rank
Federal Risk and Authorization Management Program industry classification
Industry- Product category
- Government Cloud Security Compliance
- NAICS
- Security Systems Services (except Locksmiths) (561621), National Security and International Affairs (9281)
- SIC
- Services-Management Services (8741)
- akta.pro primary industry
- Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC) (HDABAHAI)
- akta.pro secondary industry
- Cloud-Native Application Protection Platforms (CNAPP) (HDABAHAH)
Keywords
Where Federal Risk and Authorization Management Program is headquartered
LocationHeadquarters
- HQ city
- Alexandria
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Federal Risk and Authorization Management Program business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Infrastructure
Revenue model
- Federal Government Program Funding: FedRAMP is a government program under the General Services Administration (GSA) funded by federal appropriations. No commercial revenue generation.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels9 records
Federal Risk and Authorization Management Program product offering
Product offeringCore offering
FedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. It operates a centralized marketplace of 529 certified cloud services and offers two certification paths — FedRAMP 20x (modern cloud-native path) and Rev5 (legacy approach being phased out) — supported by the Consolidated Rules for 2026 (CR26) and machine-readable JSON schemas for submission artifacts.
Product overview
FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program operated by the General Services Administration (GSA) that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. The program operates primarily through the FedRAMP Marketplace—a searchable database of 529 certified cloud services—and offers two certification paths: FedRAMP 20x (the modernized path launched June 2026) and Rev5 (the legacy approach being phased out by June 2027). The Consolidated Rules for 2026 (CR26) serves as the unified reference for all certification requirements, supported by machine-readable JSON schemas for submission artifacts. FedRAMP also provides community events, a Security Inbox for urgent communications, and interactive tools like RAMPpardy trivia.
Differentiator
Problem solved
Functional benefit
Products and services
- FedRAMP Marketplace Searchable database of 529 FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors, used by federal agencies as the fast track to discovering and procuring compliant cloud solutions.
- FedRAMP 20x Modern cloud-native FedRAMP Certification path launched in 2026 providing clearer, measurable, evidence-based security demonstration with machine-readable artifacts, replacing the pilot program with wide availability on June 25, 2026. 29 services hold 20x certification as of June 2026.
- Consolidated Rules for 2026 (CR26) Unified ruleset consolidating all FedRAMP requirements, definitions, timelines, stakeholder guidance, and source material into a single public reference for agencies, cloud service providers, independent assessors, and advisors. Available in both JSON and human-readable formats.
- FedRAMP JSON Schemas Machine-readable JSON schemas defining the structure of FedRAMP certification submission artifacts including certification packages, vulnerability reports, incident reports, security decision records, and ongoing certification reports.
- FedRAMP Rev5 Legacy FedRAMP Certification approach and modified version of the original process that remains part of the FedRAMP landscape during the transition to FedRAMP 20x, especially for CSPs already working with an agency sponsor. No new Rev5 applications accepted after June 11, 2027.
Quantifiable outcome
- 529 FedRAMP Certified cloud services available on the marketplace
- +4 more outcomes
Companies that use Federal Risk and Authorization Management Program
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles4 records
Federal Risk and Authorization Management Program technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Federal Risk and Authorization Management Program partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- Federal Secure Cloud Advisory Committee (FSCAC)coreStatutory federal advisory committee established under the FedRAMP Authorization Act and Federal Advisory Committee Act. FSCAC brings together industry and government practitioners to advise on FedRAMP technical, financial, programmatic, and operational matters. Currently accepting applications for five open committee seats including Agency CISO and cloud provider representatives.
- General Services Administration (GSA)coreFedRAMP operates under GSA's Technology Transformation Services (TTS). The FedRAMP name and logo are property of GSA. Greg Barbaccia serves as Acting Director for TTS while also holding the role of Federal Chief Information Officer at OMB.
- Office of Management and Budget (OMB)coreFedRAMP aligns with OMB policy through Memorandum M-24-15. The FedRAMP Director works closely with the Office of the Federal CIO at OMB, with Greg Barbaccia serving dual roles as Federal CIO and Acting TTS Director.
- Cloud Service Providers (CSPs)coreCompanies offering cloud services seeking FedRAMP certification. The marketplace lists 529 certified services across 663 total listings including providers like Cisco, IBM, Datadog, Cloudflare, and hundreds of others.
- Independent Assessors (3PAOs)coreThird Party Assessment Organizations that evaluate cloud service providers' security controls. Recognized assessors are listed in the FedRAMP Marketplace alongside CSPs and agencies.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Federal Risk and Authorization Management Program competitors and assessment
Company assessmentBroad incumbents
- GSA Technology Transformation Services (TTS): The parent organization within GSA that operates FedRAMP. TTS is comparable because it houses multiple federal IT modernization programs (Login.gov, USWDS, Cloud.gov) alongside FedRAMP, providing shared federal-tech context and a common procurement/distribution channel.
- Cybersecurity and Infrastructure Security Agency (CISA): Federal cybersecurity agency under DHS that sets cross-sector cybersecurity standards and runs programs like the Continuous Diagnostics and Mitigation (CDM) program. Comparable because CISA drives federal cybersecurity compliance baselines that overlap with FedRAMP's cloud authorization remit.
- National Institute of Standards and Technology (NIST): NIST publishes the SP 800-53 control catalog and the Risk Management Framework on which FedRAMP is built. Comparable because FedRAMP's CR26 ruleset and 20x evidence model are derivative of NIST standards, making NIST a foundational peer in the federal compliance ecosystem.
- Defense Information Systems Agency (DISA): Operates DoD Cloud Computing (CC) SRG and Impact Levels (IL2–IL6) authorization paths for defense workloads. Comparable because DISA's cloud authorization regime is the principal alternative to FedRAMP for defense agencies, creating parallel federal cloud compliance tracks.
Emerging players
- Center for Internet Security (CIS): Publishes the CIS Controls and CIS Benchmarks used by FedRAMP-aligned and non-FedRAMP federal programs. Comparable because CIS provides the security configuration baselines that cloud operators use to demonstrate FedRAMP compliance (e.g., Secure Configuration Guide referenced in the Security Inbox test).
Regional players
- TX-RAMP: Texas Department of Information Resources program that certifies cloud services for Texas state agencies. Comparable as a state-level cloud authorization program that reuses much of FedRAMP's framework, illustrating how the FedRAMP model propagates to sub-federal jurisdictions.
Others
- FedRAMP Third Party Assessment Organizations (3PAOs): Accredited assessors (e.g., Schellman, Coalfire, A-LIGN) listed in the FedRAMP Marketplace that perform the third-party assessments required for authorization. Comparable as ecosystem participants whose business model and revenue depend directly on FedRAMP authorization volume.
- ServiceNow Federal (FedRAMP-authorized GovCloud): Major FedRAMP-authorized SaaS provider operating its GovCloud environment for federal buyers. Comparable as a representative downstream stakeholder whose federal revenue depends on FedRAMP authorization status and reuse by agencies.
Direct peers
- StateRAMP: Nonprofit that provides a government-wide security authorization framework for state, local, and education (SLED) cloud buyers, modeled on FedRAMP. Comparable because it is the closest peer in mission and product shape — a cloud security authorization marketplace with reusable authorizations — but serves SLED rather than federal buyers.
- DoD Cloud Computing Security Requirements Guide (CC SRG): DISA-managed cloud authorization regime for DoD workloads across Impact Levels. Comparable as a parallel federal cloud authorization track with overlapping security controls and a marketplace-like authorization list, but scoped to defense rather than civilian agencies.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Federal Risk and Authorization Management Program social profiles
Digital presenceFederal Risk and Authorization Management Program financial estimates
Financial estimateRevenue estimate
Valuation estimate
Federal Risk and Authorization Management Program leadership team
Management profileNumber of profiles
Profiles1 record
Federal Risk and Authorization Management Program funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Federal Risk and Authorization Management Program M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Federal Risk and Authorization Management Program
What does Federal Risk and Authorization Management Program do?
FedRAMP is a U.S. government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. It operates a centralized marketplace of 529 certified cloud services and offers two certification paths — FedRAMP 20x (modern cloud-native path) and Rev5 (legacy approach being phased out) — supported by the Consolidated Rules for 2026 (CR26) and machine-readable JSON schemas for submission artifacts.
Is Federal Risk and Authorization Management Program a public or private company?
Federal Risk and Authorization Management Program is a public company. It is classified as state government owned and is currently operating.
When was Federal Risk and Authorization Management Program founded?
Federal Risk and Authorization Management Program was founded in 2011. It employs 11 to 50 people.
Where is Federal Risk and Authorization Management Program based?
Federal Risk and Authorization Management Program is headquartered in Alexandria, United States, in the North America region.
How does Federal Risk and Authorization Management Program make money?
One revenue line is on record: federal Government Program Funding.
Who are Federal Risk and Authorization Management Program's main competitors?
Broad incumbents on record are GSA Technology Transformation Services (TTS), Cybersecurity and Infrastructure Security Agency (CISA), National Institute of Standards and Technology (NIST) and Defense Information Systems Agency (DISA). Center for Internet Security (CIS) is listed as an emerging player. TX-RAMP is listed as a regional player. Others are FedRAMP Third Party Assessment Organizations (3PAOs) and ServiceNow Federal (FedRAMP-authorized GovCloud). Direct peers are StateRAMP and DoD Cloud Computing Security Requirements Guide (CC SRG).
Does Federal Risk and Authorization Management Program have an API?
No public API is recorded for Federal Risk and Authorization Management Program.
What industry is Federal Risk and Authorization Management Program in?
Federal Risk and Authorization Management Program's product category is Government Cloud Security Compliance. Its primary akta.pro industry code is HDABAHAI, Cloud Compliance, Audit & Continuous Controls Monitoring (CCM/GRC), with a secondary code of HDABAHAH, Cloud-Native Application Protection Platforms (CNAPP). Its NAICS code is 561621 and its SIC code is 8741.